PT-2021-21108 · Selinux+6 · Selinux+6

Garrett Tucker

·

Published

2021-07-01

·

Updated

2025-11-03

·

CVE-2021-36087

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: SELinux version 3.2
Description: The issue is related to a heap-based buffer over-read in the ebitmap match any function, which is called indirectly from cil check neverallow. This occurs due to a lack of checks for invalid statements in an optional block.
Recommendations: For SELinux version 3.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALSA-2021:4513
CESA-2021_4513
CVE-2021-36087
DLA-3930-1
OPENSUSE-SU-2024:10990-1
RHSA-2021:4513
RHSA-2021_4513
RLSA-2021:4513
USN-5391-1

Affected Products

Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Selinux
Ubuntu